Skip to content

Privacy Policy

This policy explains what personal data we handle, why, on what legal basis, how long we keep it, and the rights you can exercise. It applies to our websites, our services, our products, our software, our platforms, our applications and our digital services generally, including any we introduce in future.

Scope

This policy covers all personal data we handle in the course of operating our business, including through our websites, our services, our products, our software, our platforms, our applications and our digital services. It is written to apply to offerings we introduce in future without amendment, so a new service is covered from the day it launches.

Where we operate a system on behalf of a client — for example, and without limitation, hosting or administering a platform that holds that client's own records — the client determines the purposes of that processing and we act on their instructions. In that arrangement the client is responsible for informing their own users, and this policy governs only our own handling of the data.

The data we handle

We collect only what a specific purpose requires. The categories below are illustrative of what we typically hold and are not an exhaustive list.

Categories of personal data
CategoryTypical contentsWhere it usually comes from
Contact and business detailsName, business email address, telephone number, employer, roleProvided by you when you contact us or engage us
Engagement recordsCorrespondence, requirements, meeting notes, agreements, invoicesGenerated in the course of working together
Technical and access recordsAuthentication events, administrative actions, system and security logsGenerated automatically by systems we operate or administer
Support recordsTickets, call records where telephony is in scope, and the content of support correspondenceProvided by you or generated when support is delivered
Recruitment dataApplications and supporting material, where you apply to work with usProvided by you

We do not seek special category data and ask that it is not sent to us unless a specific engagement genuinely requires it and an appropriate basis has been agreed in writing beforehand.

Why we handle it, and on what basis

Purpose and lawful basis
PurposeLawful basis where UK or EU law applies
Responding to enquiries and providing proposalsSteps taken at your request prior to entering a contract, or legitimate interests in responding to business enquiries
Delivering and supporting what we have been engaged to deliverPerformance of a contract, or legitimate interests where the contract is with your employer
Operating, securing and monitoring systemsLegitimate interests in keeping systems available, secure and auditable
Meeting accounting, tax and regulatory obligationsCompliance with a legal obligation
Establishing, exercising or defending legal claimsLegitimate interests, or compliance with a legal obligation

Where we rely on legitimate interests we have considered whether those interests are overridden by your rights, and you may object as described under Your rights below. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

Who we share it with

We do not sell personal data, and we do not share it for advertising or profiling purposes. We share it only in the following circumstances.

  • With service providers who process data on our instructions under a written agreement — for example, and without limitation, providers of hosting, communications, or business administration tooling.
  • With a client, where the data was generated in the course of work carried out for that client.
  • Where disclosure is required by law, by a court, or by a competent regulator.
  • With professional advisers where necessary for advice, audit or the defence of legal claims.
  • With a successor entity in connection with a reorganisation or transfer of the business, subject to this policy continuing to apply.

International transfers

We are established in the United States and deliver internationally, including to clients in the United States, Canada, the United Kingdom, the European Economic Area, the United Arab Emirates and the wider Middle East, Australia, and Pakistan. Personal data may therefore be transferred to, stored in, or accessed from countries other than the one you are in.

Where personal data protected by UK or EU law is transferred outside those jurisdictions, we rely on an appropriate transfer mechanism — an adequacy decision where one applies, or standard contractual clauses together with any supplementary measures the transfer requires. Where a specific engagement requires that data remain within a defined territory, that is agreed in the engagement documentation and implemented technically rather than promised generally.

How long we keep it

We keep personal data for as long as the purpose it was collected for requires, and then for any period a legal, tax, accounting or contractual obligation demands. Enquiry correspondence that does not lead to an engagement is kept only for as long as it is useful to the enquiry. Records relating to an engagement are generally kept for the duration of that engagement and for the limitation period applicable afterwards. Where we operate a system on a client's behalf, retention within that system is set by the client and configured accordingly.

Security

We apply access control on a least-privilege basis, use individual accounts rather than shared credentials for administrative access, protect data in transit using current transport encryption, restrict administrative interfaces to defined access paths, and log administrative activity. No system is immune from compromise, and any statement to the contrary should be treated with suspicion. Our practice is to reduce the likelihood of an incident and to limit what a single failure can reach.

If you believe you have found a security weakness in something we operate, please report it as described in our security policy rather than testing further.

Cookies and similar technologies

Our public website does not currently set cookies and does not run advertising, profiling or third-party analytics scripts. Where this changes, or where a platform we operate for you requires cookies to function, the position is described in our cookie policy.

Your rights

Depending on where you are and which law applies, you may have some or all of the following rights. We honour them where they apply and will tell you plainly if a specific right does not apply to your situation and why.

  • Access — to be told whether we hold personal data about you and to receive a copy.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have data deleted where there is no continuing basis for keeping it.
  • Restriction — to limit how we use data while an issue is resolved.
  • Objection — to object to processing carried out on the basis of legitimate interests.
  • Portability — to receive certain data in a structured, commonly used, machine-readable format.
  • Withdrawal of consent — where processing is based on consent.
  • Complaint — to raise the matter with the supervisory authority in your country.

Residents of certain jurisdictions have additional or differently framed rights, including the right not to be discriminated against for exercising them. Where we operate a system on behalf of a client and you are that client's customer or employee, please direct your request to that client in the first instance; we will assist them in responding.

To exercise a right, contact us using the details below. We may need to verify your identity before acting, and we will respond within the period the applicable law requires.

Children

Our services are provided to businesses and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

Changes to this policy

We update this policy when our practices change or when a legal requirement changes. The effective date is shown at the top of this page. Where a change materially affects how we handle personal data, we will take reasonable steps to bring it to the attention of affected clients rather than relying on the updated page alone.

Contact

Questions about this document can be sent to info@kyconnects.com. We aim to respond to enquiries within 4–8 business hours.

Related documents